Logs Time Series View :: Kloudfuse Docs

Logs Time Series View

The Logs Time Series interface visualizes log data as a chart over time, allowing you to apply filters, group results, and run FuseQL queries to analyze log trends and patterns.

Using the Logs Time Series interface

The Time Series interface has the following information and affordances:

01. Filters

Filters help you to narrow the search results.

To show filters, expand the filters: click the (Show filters) icon in the top left corner of the page.

To hide the filters, click the (Hide filters) icon in the top right corner of the filter panel.

02. Search logs

The Search logs searchbar enables you to find logs by any attribute value, facet, label, and so on.

The searchbar works with the Query Builder.

Follow these steps to specify the first query, :

  1. Aggregation

In the (Show) clause of the query, select from the drop-down either show all logs (default), show all fingerprints, or one of the log attributes or labels.

  1. Grouping

    In the (by) clause of the query, select from the drop-down the attribute or attributes for grouping query results.

  2. Limit

    In the (limit to) clause of the query, complete these steps:

    • Use the first drop-down to specify if you want to examine the top (default) or bottom results.
    • Use the second drop-down to specify the number of results.
  3. Step size

    In the (roll up every) clause of the query, specify the size of the time bucket for aggregating query results.

    Depending on the overall interval, the drop-down shows a different automatic rollup period, and several longer options.

  4. Function

    Click (Sigma) to add a formula to apply to the results of the query.

03. Add Query

To add a query, click (Add Query).

04. Add Formula

To add a formula, click (Add Formula).

05. Default FuseQL Search

By default, we can toggle the FuseQL Search to use the FuseQL language.

06. Overall interval

The default is Last 5 minutes. Click the drop-down to use the time picker and select the appropriate time interval.

07. Refresh display

Click (Refresh) to update the display.

08. Additional Queries

When you specify the first filter, you define the first query. Kloudfuse identifies it as query (a) in the interface. You can add additional queries, (b) and others, to your analysis.

09. Add Formula

To add a formula, click (Add Formula).

10. View type selector

The View type selector enables you to specify the search view by selecting one of the following modes:

This article discusses this view.

11. Use FuseQL

Select the Use FuseQL toggle to turn on the default Kloudfuse FuseQL.

12. Combine queries

Select the Combine all queries into one chart to combine all queries and formulas on the same graph. Deselect the option to have them appear on different (smaller) graphs.

See Combine queries and Separate queries.

13. Chart type

Click the selector for the chart type, and choose one of the options from the drop-down:

14. Create alert

Click (Create alert) to create a Log alert based on the query or queries here.

15. Export chart

Click (Export) icon to add the chart as a panel of a new or existing dashboard.

16. Explore metric

Click (Explore Metric) icon to expand the chart to full size.

17. Chart representation

The Chart that represents the time series of the logs over the specified duration.

If you specify groupings in the by clause of the query, the chart plots the groupings that result from the first grouping item.

18. Isolate Chart legend

Click a component of the Chart legend to isolate and show only these values on the chart.

Combine query charts

To combine separate charts, click to select the Combine all queries into one chart option.

Separate Query Charts

When you combine 2 or more queries on the same chart, it is relatively easy to see their relationship.

However, because the two metrics often have significantly different value ranges on the Y axis, it may be difficult to see the detail. By separating the queries into their individual charts, you vertically "expand" the axis, making it easier to visualize patterns and trends.

To separate a graph into its constituent queries, click the Combine all queries into one chart option to deselect it.